SurgiMD← Back to site

Security & Compliance

Last updated: September 10, 2026

SurgiMD handles some of the most sensitive data there is: identifiable clinical photography. This page describes the technical and organisational measures behind the app, and how they map to the major data-protection frameworks our users work under.

GDPR (European Union)

SurgiMD is designed to support GDPR-compliant use by clinics:

HIPAA (United States)

SurgiMD is built on HIPAA-eligible infrastructure and implements the technical safeguards the Security Rule expects:

We say “designed to support HIPAA compliance” deliberately: there is no such thing as HIPAA certification, and any vendor claiming one is telling you something about their marketing, not their engineering.

Dubai Health Authority & UAE health data law

SurgiMD is built in the UAE, for UAE clinicians first — and we take the local framework seriously, including Federal Law No. 2 of 2019 (ICT in Health Fields), the DHA's health data protection requirements, and Dubai's health data legislation:

The shared-responsibility model, plainly

SurgiMD gives your practice the technical safeguards; compliance is a partnership. Your clinic remains responsible for its own policies — obtaining patient consent, training staff, and using exports appropriately. We give you the tools that make doing the right thing the default: consent gates, de-identification, audit trails and locked-down storage.

This page describes SurgiMD's technical and organisational measures. It is not legal advice, and regulations vary by jurisdiction — consult your compliance officer or counsel for your specific obligations.